Professional Cloud Security Engineer
Prepare and test your skills
Prepare and test your skills
Worked example. The correct answer is already marked and every option is explained below, so there is nothing to select here. To answer questions yourself, start the free trial.
An enterprise hosts a customer-facing application on Google Compute Engine virtual machines. During a penetration test, security analysts discover a Server-Side Request Forgery (SSRF) vulnerability that allows external actors to inject custom HTTP request headers and query the instance metadata server (http://metadata.google.internal/computeMetadata/v1/instance/service-accounts/default/token). The red team demonstrated that by stealing the default Compute Engine service account token, they could leverage overly broad IAM permissions to modify the instance startup-script metadata on other production virtual machines, achieving remote code execution and privilege escalation.
Which strategy should the security engineer implement to remediate this attack vector and detect subsequent exploitation attempts?
Keep the momentum going with these hand-picked practice scenarios
Want more questions like this?
Get a free certification question every week.